Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it.
OUR MISSION
True Anomaly delivers decisive capabilities for space superiority. We build autonomous spacecraft, advanced payloads, mission software, and space-based interceptors — enabling the U.S. and its Allies to secure the space environment and counter threats from the ultimate high ground.
OUR VALUES
- Be the offset. We create asymmetric advantages with creativity and ingenuity.
- What would it take? We challenge assumptions to deliver ambitious results.
- It’s the people. Our team is our competitive advantage and we are better together.
YOUR MISSION
Your job is to find the weaknesses in our spacecraft before an adversary does. These vehicles operate in remote, contested environments, where a defect can mean loss of mission. Once one is on orbit you do not get it back, you do not get a patch window on your terms, and you do not get a second opinion. Your job is to find every weakness in the silicon, the firmware, the radios, and the software before the vehicle leaves the ground. What survives your test program could become a mission failure on orbit.
You will take flight hardware apart, with physical access being the beginning of the exercise rather than the end of it. Once you are on the board, we expect you to pivot to the software and go for root. Chain the bugs, escalate, persist, and prove out the full path an adversary would take. You will deliver the findings and the reproducible test plans that show our flight software and hardware engineers exactly where they stand, then work alongside them to close what you found.
This is an ideal role for someone who works at the intersection of hardware and software security, who would rather break a system than read about it being broken, and who wants that work to matter on a vehicle that cannot be recalled. It carries significant technical ownership and direct access to the engineers building the vehicles.
This position requires the ability to obtain and maintain a TS/SCI security clearance.
Responsibilities
Own the capability
- Advance True Anomaly's hardware security lab: tooling selection, bench design, budget case, and test methodology
- Own the security test plan for spacecraft hardware, radios, and flight software, and the schedule it runs on
Hardware and radios
- Perform invasive and non-invasive hardware attacks against flight hardware: side-channel analysis, fault injection (voltage, clock, EM), chip desoldering and rework, decapping, and exploitation of embedded debug and bus interfaces (JTAG, SWD, UART, SPI, I2C)
- Extract and reverse engineer firmware across the architectures our hardware runs on
- Analyze wired and wireless protocols, including RF links, proprietary protocols, and spacecraft command and telemetry paths
Software
- Pivot from hardware access to software exploitation: identify memory corruption and logic flaws, chain them, and escalate toward full system control
- Build coverage-guided and protocol fuzzing harnesses (AFL++, libFuzzer) and emulation-based rigs (QEMU, Unicorn) to decouple testing from hardware availability
- Root-cause findings and develop proof-of-concept exploits that demonstrate real impact and drive remediation priority
- Assess post-exploitation impact and the effectiveness of isolation, key handling, and recovery mechanisms
- Conduct security code review of flight software in C/C++ alongside binary analysis
Close the loop
- Publish findings with reproducible test plans, retest after remediation, and build automated triage and coverage analysis to keep results legible at scale
- Work with flight software and hardware engineers to implement fixes across memory safety, secure boot, cryptographic key management, and runtime hardening
- Perform threat modeling and security architecture review accounting for a sophisticated adversary and a non-recoverable asset
- Integrate security testing into HIL/SIL infrastructure and CI/CD pipelines, and support operational spacecraft with monitoring and incident response
Qualifications
Strong candidates tend to arrive from one of two directions: embedded systems engineers who moved into offensive security, or hardware and firmware security researchers who can write and review production C/C++. Real depth on both sides is rare and we are not expecting it on day one. Tell us which side you come from.
A good candidate will have:
- 5+ years of hands-on experience across embedded systems security, hardware security, or offensive security against firmware and embedded targets
- Hands-on offensive hardware experience on real boards, including side-channel analysis, voltage or clock glitching, electromagnetic fault injection, chip desoldering and rework, and decapping
- Practical experience attacking embedded debug and bus interfaces (JTAG, SWD, UART, SPI, I2C), including sniffing, injection, and firmware extraction
- A track record of independently discovering, validating, and root-causing vulnerabilities in embedded systems, firmware, or hardware
- Firmware reverse engineering across common embedded architectures, using tools such as Ghidra, IDA, or binwalk
- Solid grounding in exploitation fundamentals on constrained targets: memory corruption, exploit primitives, the mitigations you will run into, and escalation toward full system control
- Experience building your own tooling rather than only running off-the-shelf tools: coverage-guided or protocol fuzzing harnesses (AFL++, libFuzzer), emulation-based rigs (QEMU, Unicorn), test fixtures, and bench instrumentation
- Experience analyzing protocols, wired or wireless or proprietary, and reasoning about both design and implementation weaknesses
- Strong C/C++ skills with deep understanding of memory safety and secure coding practices, sufficient to review flight software at the source level
- Working understanding of hardware root of trust and secure boot, whether from implementing them or from breaking them
- Proficiency with embedded toolchains, debuggers, static analysis tools, oscilloscopes, and logic analyzers, backed by strong debugging skills
- Ability to obtain and maintain a TS/SCI security clearance
An ideal candidate will also have:
- An already-active TS/SCI security clearance
- Experience using Ghommit tool.
- Direct experience in spacecraft or satellite embedded software, or other aerospace safety-critical systems
- Experience with RF and wireless security, or with software-defined radio (SDR)
- Experience attacking or securing real-time and safety-critical systems, including timing constraints, deterministic execution, and interrupt handling
- Experience implementing secure firmware update mechanisms and anti-tamper techniques
- Experience implementing a hardware root of trust, secure boot, or key provisioning on a shipped product
- Knowledge of hardware security modules (HSMs) and secure elements
- Experience with HIL or SIL test infrastructure and embedded Linux build systems (Yocto, NixOS)
- Familiarity with space-specific protocols and standards (CCSDS, ECSS)
- A public track record of impact: CVEs, published research, conference talks, CTF results, or open-source security tooling
Compensation
Base Salary
- Long Beach, CA: $180,000 to $255,000
- Denver, CO: $170,000 to $240,000
- SF Bay Area, CA: $200,000 to $280,000
- Work Location: this role will be fully onsite at our facilities in Centennial, CO, SF Bay Area, or Long Beach, CA #LI-Onsite
- This role operates in a fast-paced, high-stakes environment where rapid decision-making and adaptability are essential
- Bias towards delivery and iteration to discover the right use cases for security investments
- Must be comfortable taking calculated risks and owning accountability for managing those risks
- Passionate about solving real-world security problems in resource-constrained embedded environments
- Collaborative culture with opportunities for significant ownership and technical leadership
- Direct access to leadership and opportunity to influence spacecraft security architecture
- Competitive salary
- Opportunity to work on cutting-edge spacecraft technology and define security standards for next-generation space systems
- Professional development and certification support
- Collaborative culture with experienced embedded systems and security professionals
- Equity + Benefits including Health, Dental, Vision, HRA/HSA options, PTO and paid holidays, 401K, Parental Leave
This position will be open until it is successfully filled. To submit your application, please follow the directions below.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us know.
To conform to U.S. Government space technology export regulations, including the International Traffic in Arms Regulations (ITAR) you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
True Anomaly is committed to equal employment opportunity on any basis protected by applicable state and federal laws. If you have a disability or additional need that requires accommodation, please do not hesitate to let us.
Skills Required
- 5+ years of hands-on experience in embedded systems development with a focus on security
- Strong C/C++ programming skills with deep understanding of memory safety and secure coding practices
- Background in low-level embedded software architecture, design, and development with security considerations
- Low-level device driver development experience with security hardening
- Proficiency with embedded systems tools, compilers, debuggers, IDEs, and static analysis tools
- Strong debugging skills
- Familiarity with embedded security standards and best practices
True Anomaly Compensation & Benefits Highlights
-
Healthcare Strength — Company and third-party materials describe 100% employer-sponsored medical, dental, and vision coverage, with HSA/FSA options noted in postings. This points to robust core healthcare support as part of total rewards.
-
Equity Value & Accessibility — Equity or stock options are consistently included in offers alongside cash compensation. Ownership is framed as a standard component of the package across roles.
-
Leave & Time Off Breadth — Public materials cite generous PTO, paid holidays, and parental leave, with some profiles noting around 25 days of PTO for full-time employees. This breadth signals meaningful paid time away in addition to holidays.
True Anomaly Insights
What We Do
Space was once the quietest place in the universe. Now, it's crowded, contested, and confrontational. We are True Anomaly: the only defense company focused exclusively on space defense. Founded in 2022 by ex-U.S. Space Force members, True Anomaly designs and builds advanced systems for space superiority: agile and powerful spacecraft platforms, mission software engineered for unmatched command and control, and payloads tailored for precision sensing and effects. True Anomaly is headquartered in Centennial, CO, with regional offices in Colorado Springs, CO, Long Beach, CA, and Washington, D.C. We are hiring and seeking exceptional talent to join True Anomaly, from any technical industry or background, to bring unique talents, perspective, and solutions. If you embrace complexity, lead instead of follow, showcase integrity over ego, take ownership for outcomes, and measure success by impact, we want to hear from you.
Why Work With Us
True Anomaly exists to enable a secure, stable, and sustainable space environment for the US, its allies, and partners. We design and build spacecraft and software solutions for space superiority. If you are ready to contribute to the future of space defense, we’d love to hear from you.
Gallery
True Anomaly Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
We are a hybrid office culture. Our employees work from offices in Denver, Colorado Springs, Los Angeles, and Washington D.C. We recognize the importance of in-office collaboration, but also the value of a flexible work and location requirements



